07 Jan 2009
More details are emerging about the man behind the recent celebrity Twitter attack everyone seems to be talking about. In case you had missed it, a hacker managed to post fictional feeds from various celebrity Twitter feeds, including CNN anchorman Rick Sanchez, Barack Obama and Britney Spears.
As Mikko Hyppönen of content security vendor F-Secure explained, it was first thought the hacker in question - a teenager known as GMZ - had directly attacked high profile accounts, but this was not actually the case.
GMZ actually used a combination of cunning, luck and technology to do his dirty work. He first targeted the account of a random, popular Twitter user, using an automated password guessing tool to get her password. Once in, he found she was actually a Twitter staffer who had access to the Twitter admin control panel - from then on it was easy to access any account he wished by resetting the passwords.
Some have cautioned that the Twitter staffer who was hacked should have used a more difficult password to crack than 'happiness', but the real fault surely lies with Twitter administrators, in letting the system allow an unlimited number of quick-fire log-in attempts.
"I feel it's another case of administrators not putting forth effort toward one of the most obvious and overused security flaws," GMZ wrote in an IM interview with the Threat Level blog. "I'm sure they find it difficult to admit it."
In the end, Twitter is pretty lucky this time that it was only embarrassed by a script kiddie. Next time, the hackers may be motivated by more malicious intent.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
EU data protection overhaul contains "bureaucratic tick box-proposals", says information commissioner Christopher Graham in exclusive interview with V3
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is one of the most successful and highly regarded...
Java/J2EE, Agile, Scrum, Test driven development, Pair...
C# / ASP.NET Software Developer - Online Gambling - London...
Developer, Gaming / Finance, 35-50k My client are...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?